LEGAL

Privacy policy

What SCORM Central collects, why, and what happens to it. Written to be read, not scrolled past.

Last updated 28 August 2026. SCORM Central is in early access; we will note material changes here and, for account holders, by email.

Who we are

SCORM Central is a Kprise product. For anything in this policy, write to hello@scormcentral.com.

What we collect

Account details. Your name, organisation, work email, and a password we store only as a hash.

Content you upload. The files you convert, the courses you build from them, and the packages the service produces. This content stays yours.

Runtime data. When a package you deliver reports back — SCORM runtime calls, completion and score data, and xAPI statements stored in the built-in LRS — we hold that data on your behalf so you can read and export it.

Usage and log data. Standard server logs: IP address, browser, pages requested, and errors, kept briefly for security and debugging.

Cookies. This marketing site sets a session cookie only when you use the contact form (to prevent forged submissions) and remembers your pricing toggle in your own browser. The app sets the cookies it needs to keep you signed in. There are no advertising or cross-site tracking cookies.

Analytics. If we measure site traffic, we use cookieless, aggregate analytics — page counts and referrers, nothing stored on your device and no individual profiles.

Payment. Card details go directly to our payment processor and never touch our servers. We see the plan, the amount, and the billing status — not the card number.

How it is used

To provide the service: converting files, generating packages and conformance reports, hosting and dispatching courses, storing statements, and supporting your account. We send service emails about your account and billing. Uploaded content and learner records are not used to train models, are not sold, and are not shared with anyone except the processors required to run the service — hosting, email delivery, and payments.

Learner data

When learners take a course you deliver, the completion and statement data belongs to your organisation; we process it on your instructions. If a learner asks us directly about their data, we will route the request to the organisation that delivered the course.

Retention and deletion

Account data is kept while your account is open. Uploaded content and built packages are kept until you delete them or close your account. LRS statements follow your plan's retention setting. Server logs are kept for a short, fixed window. When you close your account, or ask us to, we delete your content and account data within 30 days, except what we must keep for tax and accounting.

Security

Traffic is encrypted in transit and access to production data is restricted to the people who operate the service. If you believe you have found a security issue, contact hello@scormcentral.com and we will respond quickly.

Your rights

You can ask for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. Email hello@scormcentral.com from your account address and we will act on it.